Privacy Policy
Your privacy matters. RafterCore is committed to handling your personal information with transparency, care, and respect. This policy explains exactly what we collect, why we collect it, how we use it, and what rights you have.
Table of Contents
- Who We Are
- Information We Collect
- How We Use Your Information
- How We Share Your Information
- Data Storage & Security
- Data Retention
- Your Rights & Choices
- Cookies & Tracking
- Children's Privacy
- Third-Party Services
- California Privacy Rights (CCPA)
- GDPR — EU & UK Rights
- International Users
- Changes to This Policy
- Contact Us
1. Who We Are
RafterCore is operated by RafterCore LLC, a Phoenix, Arizona-based company providing a SaaS platform for roofing contractors and homeowners. References to "RafterCore," "we," "us," or "our" throughout this policy refer to RafterCore LLC.
For privacy inquiries, contact us at: contact@raftercore.com or 1-833-723-8371.
2. Information We Collect
Information you provide directly:
| Category | Examples | Purpose |
|---|---|---|
| Account info | Name, business name, email, password, phone, city, state | Account creation and authentication |
| Business data | Client records, job details, invoices, photos, estimates, team member info | Core platform functionality |
| Payment info | Billing email (card numbers handled entirely by Stripe) | Subscription billing |
| Communications | Support messages, booking requests, client communications | Customer support and platform features |
Information collected automatically:
- Usage data — pages visited, features used, session duration, click patterns
- Device data — device type, operating system, browser type, screen resolution
- Log data — IP address, access timestamps, error logs
- Location data — approximate city/region based on IP, used for storm alerts. We do not track precise GPS location without explicit consent.
3. How We Use Your Information
We use your information to:
- Provide, operate, and maintain the RafterCore platform
- Process subscription payments and invoice transactions via Stripe
- Deliver platform features including AI roof analysis, storm alerts, and booking notifications
- Send booking confirmations and service-related notifications
- Provide AI-powered features including roof scanning, supplement letter generation, and prospect building
- Send transactional and account-related emails (password resets, receipts, subscription notices)
- Respond to support requests and communicate with you
- Detect and prevent fraud, abuse, and security incidents
- Analyze usage patterns to improve the platform (using aggregated, anonymized data)
- Comply with legal obligations
We do not use your data to serve third-party advertising. We do not sell your data to data brokers.
4. How We Share Your Information
We share your data only in these circumstances:
Service providers (data processors):
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing | Email, subscription details |
| Supabase | Database & authentication | All account & business data |
| Anthropic Claude | AI features | Address/property queries, job context |
| Vapi.ai | AI voice calls | Customer phone, name, booking details |
| Vonage | SMS messaging | Phone numbers, message content |
| Calendar integration | Booking details with your consent |
Each provider operates under its own privacy policy and our data processing agreements requiring them to protect your data.
Between merchants and customers: When a homeowner books through your customer portal, their contact information is shared with you as the merchant. This is core to the platform's function.
Legal requirements: We may disclose information when required by law, court order, or government authority, or to protect the rights, property, or safety of RafterCore, our users, or the public.
Business transfers: If RafterCore is acquired or merged, your information may be transferred as part of that transaction. We will notify you in advance.
5. Data Storage & Security
Your data is stored in Supabase's cloud infrastructure with the following protections:
- Encryption in transit — All data transmitted between your device and our servers uses TLS 1.3
- Encryption at rest — Database storage is encrypted
- Row-level security — Each merchant can only access their own data
- Access controls — Production system access is restricted to authorized personnel only
- No card storage — Payment card data is handled entirely by Stripe and never stored on RafterCore servers
While we take security seriously and implement industry-standard protections, no system is completely secure. We cannot guarantee absolute security of your data.
6. Data Retention
- Active accounts — Data is retained for as long as your account is active
- After deletion request — Personal data is removed within 30 days
- Financial records — Invoice and payment records may be retained for up to 7 years for accounting and legal compliance
- Backup purge — Encrypted backups are overwritten within 90 days of account deletion
7. Your Rights & Choices
Request a copy of the personal data we hold about you.
Request correction of inaccurate or incomplete data.
Request deletion via our Delete Account page.
Request an export of your data in a machine-readable format.
Unsubscribe from marketing emails at any time via the unsubscribe link.
Request that we restrict processing of your data in certain circumstances.
To exercise any of these rights, email us at contact@raftercore.com. We will respond within 30 days.
8. Cookies & Tracking
RafterCore uses browser localStorage (not traditional cookies) to store your session data, preferences, and cached business data for offline use. We do not use:
- Third-party advertising cookies
- Cross-site tracking pixels
- Behavioral targeting technologies
- Social media tracking buttons
If we add analytics tools in the future, we will update this policy and notify users accordingly.
9. Children's Privacy
RafterCore is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal data, please contact us at contact@raftercore.com and we will promptly delete it.
10. Third-Party Services
Our platform links to and integrates with third-party services. When you use these integrations, you are also subject to those parties' privacy policies. We recommend reviewing the privacy policies of:
Lawful Basis for Processing (GDPR)
Where GDPR applies, RafterCore processes personal data under one or more of the following lawful bases:
- Contract performance — processing necessary to deliver the services you subscribed to (job management, invoicing, scheduling, customer portal access)
- Legitimate interests — fraud prevention, platform security, abuse detection, product analytics that improve the service
- Legal obligation — retaining financial records and responding to lawful requests from authorities
- Consent — marketing emails, optional notifications, and any processing where we explicitly ask for your permission
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, RafterCore will:
- Notify affected users without undue delay and within 72 hours of becoming aware of the breach (GDPR requirement)
- Notify the relevant supervisory authority where required by applicable law
- Provide a description of the breach, categories of data affected, likely consequences, and measures taken
To report a suspected breach or vulnerability, contact contact@raftercore.com with "Security" in the subject line.
11. California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
- The right to know what personal information we collect and how it is used
- The right to delete personal information we hold about you
- The right to opt-out of the sale of personal information (we do not sell personal information)
- The right to non-discrimination for exercising your CCPA rights
To submit a CCPA request, email contact@raftercore.com with "CCPA Request" in the subject line.
12. International Users
RafterCore is operated in the United States. If you access the platform from outside the US, your data will be transferred to and processed in the US. By using RafterCore, you consent to this transfer. We ensure appropriate safeguards are in place for any international data transfers.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Sending an email to the address associated with your account
- Displaying a prominent notice within the RafterCore platform
The "Last updated" date at the top of this page reflects the most recent revision. Continued use of RafterCore after changes take effect constitutes acceptance of the updated policy.
14. Contact Us
For privacy-related inquiries, data requests, or concerns:
RafterCore / RafterCore LLC
Email: contact@raftercore.com
Phone: 1-833-723-8371
Response time: within 30 days for data requests, within 5 business days for general inquiries.
12. GDPR — EU & UK Resident Rights
If you are located in the European Union, European Economic Area, or United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) and UK GDPR:
- Right of access — request a copy of all personal data we hold about you (Subject Access Request)
- Right to rectification — correct inaccurate or incomplete personal data
- Right to erasure ("right to be forgotten") — request deletion of your personal data where there is no legitimate reason for us to continue processing it
- Right to restriction — request that we restrict processing of your data in certain circumstances
- Right to data portability — receive your data in a structured, machine-readable format and transmit it to another controller
- Right to object — object to processing based on legitimate interests, including profiling
- Rights related to automated decision-making — not be subject to solely automated decisions that produce legal or similarly significant effects
- Right to withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing
International Data Transfers
RafterCore is operated from the United States. If you access our platform from the EU, EEA, or UK, your data will be transferred to and processed in the US. We rely on the following safeguards for international transfers:
- Standard Contractual Clauses (SCCs) — our sub-processors (Supabase, Stripe, Resend, Anthropic) have executed SCCs approved by the European Commission
- UK International Data Transfer Agreement (IDTA) — for transfers to and from the United Kingdom
Data Protection Officer
RafterCore does not currently meet the threshold requiring a formal DPO appointment. Privacy inquiries are handled by our founding team. Contact: contact@raftercore.com — Subject: "GDPR Request".
Supervisory Authority
You have the right to lodge a complaint with your local supervisory authority. EU residents may contact their national data protection authority. UK residents may contact the ICO (ico.org.uk).
To exercise any GDPR right, email contact@raftercore.com with "GDPR Request" in the subject line. We will respond within 30 days.